汤姆·多尔曼_所有你的秘密属于我们利用固件漏洞破解TEEs.pdf

编号:175469 PDF 58页 1.03MB 下载积分:VIP专享
下载报告请您先登录!

汤姆·多尔曼_所有你的秘密属于我们利用固件漏洞破解TEEs.pdf

1、#BHUSA BlackHatEventsAll Your Secrets Belong to Us:All Your Secrets Belong to Us:Leveraging Firmware Bugs to Break TEEsLeveraging Firmware Bugs to Break TEEsTom Dohrmann#BHUSA BlackHatEventswhoamiTom DohrmannLow-level enthusiastCodingHacking#BHUSA BlackHatEventsOutlineShort Intro to TEEs and AMD SEV

2、-SNPPrerequisitesPlatform Security Processor&FirmwareReverse Map TableBug#1Simple ExploitImproved ExploitBug#2ExploitWrap-up and take-aways#BHUSA BlackHatEventsWhats a TEE Anyway?TEE=Trusted Execution Environment A secure area of a main processor Workloads are protected from conventionally privilege

3、d parts of an OS e.g.the kernel For a lot of applications leakage of secrets is a bad as arbitrary code execution.Many implementations:AMD SEV(-ES/-SNP)Intel SGX,Intel TDX Arm TrustZone,Arm CCA IBM SE RISC-V CoVE NVIDIA H100“Compromising Confidential Compute,One Bug at a Time”#BHUSA BlackHatEventsVe

4、ry Short Intro to AMD SEV-SNP AMD SEV-SNP implements a Trusted Execution Environment(TEE).It aims to shield protected virtual machines from untrusted and even malicious hypervisors.All data and code is encrypted and integrity protected.Upon creation of a VM,the initial memory contents are measured a

5、nd can be verified through attestation reports.#BHUSA BlackHatEventsPlatform Security Processor(PSP)The Platform Security Processor is a highly privileged components of AMD SoCs.In the context of SEV,the PSP implements the root of trust and is required to create,attest,migrate,delete SEV-SNP virtual

6、 machines.The SEV firmware is also used with the SEV-SNPs predecessors,SEV and SEV-ES.The firmware can be live-updated.Parts of the firmware were published in August 2023.#BHUSA BlackHatEventsReverse Map Table(RMP)The RMP is used to protect the integrity of memory.It contains an entry for every gues

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(汤姆·多尔曼_所有你的秘密属于我们利用固件漏洞破解TEEs.pdf)为本站 (张5G) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠